A threat actor claims to have stolen a database from Kodex containing more than 250,000 user accounts and extensive records associated with law enforcement data requests after allegedly gaining access through an exposed administrative API.
The database was offered for sale on an underground cybercrime forum on Aug. 25 for $2,000. The seller claims the material was obtained directly from Kodex’s backend and includes user accounts, government agency information, legal request records, preservation requests, non-disclosure orders and more than 1.28 million activity logs.
BreachNews has not independently verified the database or the claimed method of access. The seller did not publicly provide sufficient evidence to establish that the full dataset is authentic.
Seller claims 251,384 Kodex accounts
According to the forum listing, the allegedly stolen database contains 251,384 user accounts with information including names, email addresses, phone numbers, agency affiliations, roles and access levels.
The threat actor further claims the database contains information associated with more than 15,000 law enforcement agencies, 187,462 records requests, 41,208 preservation requests and 9,743 non-disclosure orders.
Another 1,284,517 request activity logs allegedly contain IP addresses and timestamps. The seller also claims administrative and agent accounts are represented in the database, along with information about account access levels and multi-factor authentication status.
BreachNews is not publishing individual account information, case numbers, IP addresses, legal request details or other potentially sensitive records allegedly contained in the database.
Kodex handles sensitive government data requests
Kodex operates infrastructure used by companies and government agencies to manage and verify requests for user information, including subpoenas, warrants, court orders, preservation requests and emergency disclosures.
According to Kodex, its platform verifies requesters, encrypts exchanges and maintains records of how requests are processed. The company says its Kodex Global Network connects approximately 15,000 government agencies and more than 150,000 verified investigators.
The overlap between those publicly stated figures and the numbers in the seller’s post is notable, but it does not independently establish that the advertised database originated from Kodex. Some of the figures could have been derived from publicly available company information.
Kodex’s role in the law enforcement request process makes the allegation particularly sensitive. The company positions its platform as a security layer designed in part to prevent criminals using compromised government accounts or fraudulent legal requests from obtaining user information from technology companies.
Exposed admin API allegedly used for access
The seller claims the database was obtained through an exposed administrative API on Kodex’s backend, but provided no technical details sufficient to validate that assertion.
No vulnerability identifier, affected software component or independently verifiable evidence of the alleged access method was disclosed in the public listing. It is therefore unclear whether an administrative interface was actually exposed, whether credentials were compromised, or whether the database was obtained through another method.
The distinction is important because Kodex itself provides API-based functionality as part of its platform. The existence of legitimate APIs does not substantiate the seller’s claim that an administrative API was improperly exposed.
Potential impact extends beyond account data
If the database is authentic, the more significant concern may be the alleged exposure of information surrounding law enforcement requests rather than the user account count alone.
Records describing legal processes, preservation requests, non-disclosure orders and request activity could reveal sensitive information about government investigations or investigative workflows. Account and authentication metadata could also create additional risks if it can be used to identify or target personnel with access to law enforcement request systems.
Kodex has previously warned about criminals compromising law enforcement email accounts and using fraudulent government requests to obtain sensitive information from companies. The company says requester verification and continuous monitoring are designed to prevent compromised credentials alone from providing unrestricted access to its network.
At time of publication, BreachNews had not identified a public statement from Kodex addressing the Aug. 25 breach claim. The alleged database remains offered for sale as a purported one-time transaction.
BreachNews will update this article if Kodex confirms or disputes the incident, or if additional evidence establishes the authenticity or origin of the advertised data.












